122
seidengroup.com ZendCon 2016 https://joind.in/talk/34c69 DB2 and PHP In Depth on IBM i

DB2 and PHP in Depth on IBM i

Embed Size (px)

Citation preview

Page 1: DB2 and PHP in Depth on IBM i

seidengroup.com ZendCon 2016https://joind.in/talk/34c69

DB2 and PHP In Depth on IBM i

Page 2: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Seiden Group and Club Seiden

Alan is a leader and expert in PHP on IBM i; leader, Zend’s PHP Toolkit for IBM i; and “Performance guru of PHP on IBM i”

Seiden Group is a team of experts available for mentoring/troubleshooting/project advice/development.

seidengroup.com, [email protected]

2

Page 3: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Contact

3

Alan Seiden

[email protected]

201-447-2437

www.SeidenGroup.com twitter: @alanseiden

Page 4: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Today’s discussion will include:

• Uniqueness of DB2 for IBM i • Which DB2-enabled middleware to use with PHP • Securing your SQL with prepared queries • Connection options for speed and reliability

§ Persistent connections § Library lists

• What’s NEW in ibm_db2 • Connecting from “off the box” • Many other tips

4

Page 5: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Why learn DB2 best practices?

•As chief database on IBM i, DB2 runs these: •Most transaction processing systems •Stored procedures •“XMLSERVICE” Toolkit

• Accessible with db2 stored procedures from PHP

•DB2 knowledge will help you: •Maximize speed •Reduce CPU usage •Maximize reliability

• Avoid unexpected locking and other operational problems

5

Page 6: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Heart of IBM i is DB2

• DB2 built in § Transaction processing workhorse § Database implemented below operating system level!

• IBM i’s “Machine Interface (MI)” between OS and hardware § Journaling, auditing, commitment control very commonly used § Never corrupted

• Doesn’t lose data even if knock out power plug

• Database often taken for granted § So self-managing, DBAs are rare

6

Page 7: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Reliable

7

Page 8: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Nondisruptive business growth

• Scales vertically § One system can handle large and diverse workloads

• Total Cost of Ownership (TCO), including reduced operator costs, is said to be competitive or cheaper than assembling server farms

§ Can activate additional processors without restarting system

• Dependable § Resistant to viruses

• Object-based system since the 1970s § Journaling, commitment control, replication, high availability § Security features galore § Keeps on running

• You will sleep soundly at night

8

Page 9: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

IBM i can “phone home”

9

Page 10: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Data and programs last forever

• IBM has been dedicated to legacy app longevity and data longevity § RPG (and occasionally COBOL) running for 30-40 years § DB2 data evolving 30-40 years § Middleware insulates applications from hardware changes

10

IBM i Heritage chart from Trevor Perry http://blog.angustheitchap.com/?p=415

Page 11: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Long-serving back ends, new front ends

• What does this mean to you?

§ RPG and DB2, mature and evolving for years, can be part of your data model, accessed by PHP

§ Create web GUI interfaces and web services around these venerable resources

• Business logic is encapsulated in RPG/COBOL/DB2 • You can keep your hands somewhat clean of business details

11

Page 12: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

DB2 on IBM i is…

•Fully integrated business database • Coded at the kernel level (below the OS)

• Other database systems are .exe files

• User profiles = real IBM i user profiles • Security, logging, auditing consistent throughout the system • Other databases have “pretend” users whose security is enforced

only by database code

•Always present and available • No daemon that can be ended or hacked • “Who shut down the database?” Not on IBM i!

12

Page 13: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

DB2 on IBM i is…

• Indestructible, low maintenance (cost-effective) • Data corruption almost unheard of • 30+ years of work for reliability and throughput • DBA-less operation. Scale vertically. Add disk and go!

• DB2 on i isnot this:

13

Disclaimer: Not singling out other databases as “bad.” A NoSQL database such as Mongo prizes flexibility more than management ease

Page 14: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Database jargon

• Modern and traditional IBM i terminology coexist

* a logical file resembles an “index + view” Modern views, triggers, etc. are supported by DB2.

14

Modern term Traditional term or phraseSchema LibraryTable File or Physical FileIndex Logical File*Row RecordColumn Field

Page 15: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Tip: LF indexes used automatically

• Logical file keys treated as indexes by SQL

• To take advantage of LF “indexes,” use ORDER BY, WHERE, and JOIN in your SQL as usual § Indexes from LFs will be chosen automatically as appropriate § No need to specify LF in SQL: use physical file/table

• If your preferred indexes aren’t selected by the optimizer, try Visual Explain to learn why. § http://www.ibmsystemsmag.com/ibmi/developer/general/

visual_explain/ § Visual Explain runs in Access Client Solutions (ACS) and the

older IBM i Navigator.

15

Page 16: DB2 and PHP in Depth on IBM i

Prerequsites for DB2 with PHP

Page 17: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Zend Server for IBM i

• Download Zend Server 8.x • http://www.zend.com/en/products/server/downloads-ibmi

• Easy upgrade from 6.x • Includes ibm_db2 version 1.9.7

with many updates

• Editions • Basic (free), Professional, Enterprise • http://www.zend.com/en/products/server/editions • Same download, different license

17

Page 18: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

DB2 is an exciting growth zone for IBM i

• Behooves you to stay on top of it

• Example of update: • http://www.mcpressonline.com/ibm-i-os/400-i5/os/step-right-up-

and-hear-about-db2-and-tr9.html • Regular expressions in WHERE clause • System info available via SQL…joblog, liblist, more

18

Page 19: DB2 and PHP in Depth on IBM i

Alan’s current favorite features

Page 20: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

A select list of features (1 of 2)

• SQL Views § Act like a table (SELECT) but implements “virtual” logic

• User defined functions (UDF) § Less functionality than the others (generic) § “Free” connections from other platforms

• Stored procedures § Efficient, flexible § Good place for business logic § Run multiple queries if desired

more…

20

Page 21: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

A select list of features (2 of 2)

• VARCHAR/Trim § Avoid extra spaces caused by fixed-length strings

• Web service support § DB2 can retrieve/send HTTP data and parse XML

21

Page 22: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Views

• Like old “join logical” file and much more create view presllmstj1 (programcode, programdesc, item, orderbydate, orderbydate_mmddyy, expired) as select  trim(pccode), trim(pcdesc), pmprod, pmobdate,  mmddyy_slashes(pmobdate),CASE WHEN CURRENT_DATE > PMOBDATE THEN 1 ELSE 0 END as expired  from PRESLLMST left join PRESLLCDE on PMCODE = PCCODE   

select * from presllmstj1

22

Page 23: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

User-defined functions (UDF)• Create your own function in DB2

e.g. 6 digit numeric date mmddyy to real date old way: select date(substr(digits(phdate),1,2) || '/' || substr(digits(phdate),3,2) || '/' || substr(digits(phdate),5,2)) as podate from podet inner join pohead on pipo=phpo where piprod = 4317140;

CREATE FUNCTION mmddyy_to_date (thedate numeric(6,0)) RETURNS DATE LANGUAGE SQL BEGIN RETURN date(substr(digits(thedate),1,2) || '/' || substr(digits(thedate),3,2) || '/' || substr(digits(thedate),5,2)); END New way: select MMDDYY_TO_DATE(phdate) as podate from podet inner join pohead on pipo=phpo where piprod = 4317140

23

Page 24: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Stored procedures

• Most flexible. • Multiple queries, resultsets, call RPG, SQL, all

sorts of logic, parameters

24

Page 25: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Varchar/trim

• VARCHAR/Trim § Avoid extra spaces caused by fixed-length strings § <input type=text name='srvczip' size=9 value="43031 "

id="srvczip" maxlength="9">

• Extra spaces caused by CHAR (fixed length strings)

• Use VARCHAR instead for automatic trimming or trim(MyField) in SQL

25

Page 26: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Web services

• DB2 can GET/POST HTTP • Parse XML • So DB2 can be a web service engine

• See my presentation on “PHP Tricks for RPG developers”

26

Page 27: DB2 and PHP in Depth on IBM i

DB2 drivers

Page 28: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Choice of middleware to access DB2

• Zend Server includes at least three such extensions:

• odbc § Less functionality than the others (generic) § “Free” connections from other platforms

• IBM_PDO § PDO = PHP Data Objects § Generic DB2. Experimental “/” separator and library lists

• ibm_db2 § Provides IBM i-specific features such as library list support

28

Page 29: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

ibm_db2 documentation

• Manual page § http://php.net/ibm_db2

• Source code and additional documentation at the “PECL” PHP extension repository § http://pecl.php.net/package/ibm_db2 § Read the “C” source sometime—it’s educational

• We will examine ibm_db2 in detail today

29

Page 30: DB2 and PHP in Depth on IBM i

Connect to DB2

Page 31: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Connect with db2_connect()

• db2_connect() creates a database connection § Accepts four parameters that you should master

• Three string parameters • One array of optional options

• resource db2_connect (string $database, string $username, string $password [, array $options ])

• db2_pconnect() is similar § pconnect creates persistent connections (more on that later)

31

Page 32: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

db2_connect() string parameters • $database

§ Leave blank ('') for default local database § Use a db name from WRKRDBDIRE for a choice of

databases • Database name can be *LOCAL or that of an LPAR, IASP

(Independent auxiliary storage pool), or another machine

• $username § Leave blank ('') for default Apache user (QTMHHTTP)

• Not recommended § Use any valid user profile to associate queries with that user

• $password § Leave blank ('') if $database and $username were blank § Otherwise, provide password corresponding to $username

32

Page 33: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

db2_connect() basic examples

• Empty params § $conn = db2_connect('', '', ''); § Connects to local database with web user QTMHHTTP § Not recommended: may be disallowed in future release

• Better: use specific values § $conn = db2_connect('MYDB', 'MYUSER', 'MYPASS');

§ Connects to MYDB database (must be configured in WRKRDBDIRE) with user MYUSER

33

Page 34: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

How to connect to remote DB or iASP

•Connect to another partition, server, or iASP as if local •Useful for testing PHP scripts against databases of

multiple partitions (dev/test/production)

•Example: remote server is at IP 1.2.3.4 and has database named SANJOSE

•We will refer to it on our box with alias “DEVBOX” •Use WRKRDBDIRE (Work with Relational Database

Directory Entries) to create local alias to remote database

34

Page 35: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

WRKRDBDIRE to set up alias

35

Page 36: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Now we can access “DEVBOX” database

• User and password must be correct for the remote database

$db = db2_connect('DEVBOX', 'DEVUSER', 'DEVPWD');

36

Page 37: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Fourth parameter (array $options)

• Optional array to fine-tune the connection • Below are choices that are most relevant for IBM i • Details as we go

• i5_lib • Set a single default library

• i5_naming • Choose “system” or SQL naming

• i5_libl • Set a library list (be sure to set i5_naming on)

• i5_commit • Commitment control options

• autocommit • DB2_AUTOCOMMIT_ON (default) or _OFF

37

Page 38: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

i5_lib

• Specify one library as default § 'i5_lib'=>'MYLIB'

• Any unqualified files/tables will be assumed to use this library

38

Page 39: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

i5_naming for library lists

• DB2_I5_NAMING_ON § A constant equal to 1 that turns on “system naming” mode § Table files qualified using the slash (/) delimiter § Unqualified files are resolved using the library list for the job

• DB2_I5_NAMING_OFF § A constant equal to 0 (default) that enables “SQL naming”

mode § Table files qualified using the period (.) delimiter § Unqualified files are resolved using either the default library

(i5_lib) or the user profile name specified on db2_connect() (could be QTMHHTTP)

• Message to watch for: MYTABLE in YOURNAME type *FILE not found. SQLCODE=-204”

39

Page 40: DB2 and PHP in Depth on IBM i

User profile strategy

Page 41: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Three techniques (1 of 3)

• Small number of "system" user profiles. One user per library list. When "real" user signs in, authenticate against a database, LDAP, etc. Not against user profile list

41

Page 42: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Three techniques (2 of 3)

• db2_connect with real user profile§ user can get disabled when wrong password is

entered§ revealing an actual user profile to end users (OK for

internal. security problem if external)§ benefit: authority, program logic, journal entries will

work with "real" IBM i user profile

• db2_pconnect works the same except that the jobs stay semi-active, visible to operator

42

Page 43: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Three techniques (3 of 3)

• db2_pconnect with generic "system" profile but then switch to "real" profile after authentication• fast connection• limits number of active jobs• performance cost of the "switch"• security concerns about mixed generic/specific user

profile attributes/authority in a job• need to "switch back" afterward

43

Page 44: DB2 and PHP in Depth on IBM i

Included sample script

Page 45: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Included with Zend Server“SQL Access” sample script illustrates several techniques from this talk

Page 46: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Snippet of sample script/* Construct the SQL statement */$sql = "SELECT * FROM ZENDSVR.SP_CUST WHERE CUST_ID > ? FOR FETCH ONLY";

/* Prepare, bind and execute the DB2 SQL statement */$stmt= db2_prepare($conn_resource, $sql);$lower_limit = 1220; //from the CUST_ID value$flds = db2_num_fields($stmt);if($flds > 0 ){//show Table Header (analyze result set)

echo "<table border=1>";echo "<tr>";for($i=0; $i<$flds; $i++){

echo '<td width="20%">';$name = db2_field_name($stmt, $i);echo $name;echo "</td>";

}

echo "</tr>";

//Execute statement , uses a binding of parameters db2_bind_param($stmt, 1, "lower_limit", DB2_PARAM_IN);$result = db2_execute($stmt);

Page 47: DB2 and PHP in Depth on IBM i

Commitment control

Page 48: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Assure data integrity

• Commitment control allows “all or none” logic when running multiple update/insert/delete queries

• If one query fails, roll back previous related queries

• Example: If a detail record update fails, roll back the header update

• Requires that journaling be enabled on files/tables being written to

48

Page 49: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Use commitment control for data integrity

• Example: “all or none” for two INSERTS § with ibm_db2.i5_allow_commit = 1 § and autocommit = DB2_AUTOCOMMIT_OFF

$conn = db2_pconnect('', '', '', array('autocommit'=>DB2_AUTOCOMMIT_OFF));

$stmt=db2_prepare($conn,"INSERT INTO MYTABLE (IDNUM, NAME) VALUES(?, ?)");

$result1 = db2_execute($stmt, array(1, 'jane')); // should insert OK

$result2 = db2_execute($stmt, array('x', 'bob')); // not numeric!

// check if both INSERTs succeeded

if ($result1 && $result2) {

// Success. Commit both inserts

db2_commit($conn);

} else {

// *** Error with one of the inserts; roll them both back ***

db2_rollback($conn);

}

// Neither record will be in the table. We rolled back.

49

Page 50: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

i5_commit

• i5_commit § Options for isolation level § Gives you fine-grained control (and ability to turn off altogether) § Before Zend Server 8.5, must also enable commitment control

system-wide • ibm_db2.i5_allow_commit = 1 in INI file

§ Choices: • DB2_I5_TXN_NO_COMMIT – turns off commitment control for this

connection • DB2_I5_TXN_READ_UNCOMMITTED • DB2_I5_TXN_READ_COMMITTED • DB2_I5_TXN_REPEATABLE_READ • DB2_I5_TXN_SERIALIZABLE

50

Page 51: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

autocommit

• DB2_AUTOCOMMIT_ON § A constant equal to 1 (default) § Turns autocommit on

• End of script causes commit § Only relevant when commitment control is used § Convenient: insert/update/delete will work without db2_commit()

• DB2_AUTOCOMMIT_OFF § A constant equal to 0 § Turns autocommit off § Only relevant when commitment control is used § Provides flexibility to ensure data integrity in multi-step transactions by

using db2_commit()/db2_rollback() around groups of insert/update/delete queries

51

Page 52: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Commitment control tips

• In php.ini: § To use commitment control before 1.9.6-sg25, set

ibm_db2.i5_allow_commit = 1

• In db2_connect() option array: § Modify default settings with ‘i5_commit’ option § Choose ‘autocommit’ on or off

• Turn on journaling for schemas (libraries) § Already on if schema created via “CREATE SCHEMA” (SQL/DDL) § Extra step needed for libraries created via CRTLIB

• Start Journal Library (STRJRNLIB, v6.1+) makes a library a journaled object. Any objects eligible to be journaled that are added to the library can be automatically journaled

• http://www.redbooks.ibm.com/abstracts/tips0662.html

52

Page 53: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

More about db2_connect, db2_pconnect

•Manual pages §http://www.php.net/manual/en/function.db2-

connect.php §http://www.php.net/manual/en/function.db2-

pconnect.php §http://www.php.net/manual/en/features.persistent-

connections.php

53

Page 54: DB2 and PHP in Depth on IBM i

Security

Page 55: DB2 and PHP in Depth on IBM i

Prepare queries

Page 56: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

“Prepared” = safe and fast

• Prepared queries help in several ways § Eliminate errors due to un-escaped single quotes § Protect your data from SQL Injection attacks § Speed up repeated queries

• They are also known as prepared statements

• Here’s an example of the mischief they prevent

56

Page 57: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Apostrophes confuse query parsers

// mysite.com?name=whatever $name = $_GET['name']; $sql = "select custno from custfile where name = '$name' and status = 'ACTIVE' ";

• Do you see any potential problems?

• What if the name is “O’Shea” ? Error! $sql = "select custno from custfile where name = 'O'Shea' and status = 'ACTIVE' ";

• Single quotes confuse query parser when they serve two purposes § Used as apostrophe in data § Delimiter of string literals in the SQL syntax

57

Page 58: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Malicious users can try “SQL Injection”

// mysite.com?name=whatever $name = $_GET['name']; $sql = "select custno from custfile where name = '$name' and status = 'ACTIVE' ";

• What if the name is the weird-looking “x' OR 1=1--” (That is, a user typed: mysite.com?name=x' OR 1=1-- ) $sql = "select custno from custfile where name = 'x' OR 1=1--' and status = 'ACTIVE' ";

• Every record in the table will be selected § OR 1=1 will always be true § -- turns subsequent ‘where’ criteria into a comment (ignored!)

58

Page 59: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Safeguard data with prepared queries

// mysite.com?name=whatever $name = $_GET['name']; $sql = "select custno from custfile where name = ? and status = 'ACTIVE' ";

• Represent parameters with question marks (?) instead of literal values

• It’s fine to retain hard-coded values in the query § Such as ‘ACTIVE’ in the example above

• Supply parameters in an array § $params = array(“O'Shea”);

• Full example on next slide

59

Page 60: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

db2_prepare() with db2_execute()

$name = $_GET['name']; $conn = db2_connect('','',''); $sql = "select custno from custfile where name = ? and status = 'ACTIVE' ";

$params = array($name); // can be "O'Shea" for all we care $stmt = db2_prepare($conn, $sql); if ($stmt) { // prepared OK $result = db2_execute($stmt, $params); if ($result) { // ran query OK with parameters while ($row = db2_fetch_assoc($stmt)) { echo "$row['custno']\n"; } } }

60

Page 61: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Ordinary db2_exec() re-calcs plan

• Ex. of non-prepared SQL repeated with different params $values = array('acme', 'shoprite', 'stop n shop'); foreach ($values as $value) { $sql = "select custno from custfile where name = '$value' and status = 'ACTIVE' ";

// query gets re-optimized in each iteration $stmt = db2_exec($conn, $sql); if ($stmt) { // do something with $stmt } }

• The query plan will re-optimize on each db2_exec() because a new SQL string was supplied each time

• OK for one-off queries but not when repeated

61

Page 62: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Prepared statement allows re-use of plan

• Ex. of prepared SQL; execution with different params // prepare the query ONCE $sql = "select custno from custfile where name = ? and status = 'ACTIVE' ";

$stmt = db2_prepare($conn, $sql); // now execute with values only $values = array('acme', 'shoprite', 'stop n shop'); foreach ($values as $value) { $result = db2_execute($stmt, array($value)); if $result {// do something with $stmt } }

• The query plan is calculated ONCE and reused with each db2_execute(), saving time and CPU

62

Page 63: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Prepared statements/queries are best

• Replace db2_exec() with db2_prepare() and db2_execute()

• Benefits § Queries will run as intended, with fewer surprises § Protection from a common form of hacking (SQL injection) § Performance will improve for repeated queries

63

Page 64: DB2 and PHP in Depth on IBM i

RCAC

Page 65: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

New security technique

• Row and Column Access Control (RCAC) • In IBM i 7.2+ • Implemented via additional SQL “WHERE” clauses and more

• Row control: limit what rows can be selected, at the database level, depending on the user or any other criteria

• Column Access: mask or manipulate columns at the database level

• Will restrict in all applications • More info

• http://www.ibmsystemsmag.com/Blogs/i-Can/September-2014/IBM-i-7-2---Protect-Data-With-RCAC/

65

Page 66: DB2 and PHP in Depth on IBM i

Debug/diagnostics

Page 67: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Functions to get error codes/messages

•db2_conn_error() connection error code •db2_conn_errormsg() connection error text •db2_stmt_error() prepare/execute error code •db2_stmt_errormsg() prepare/execute error text

67

Page 68: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Connections return a resource or false

$conn = db2_connect("*LOCAL", "MYUSER", "BADPASS");

// test for falseif (!$conn) {

echo "Connection failed. SQL Err: ";echo db2_conn_error() . "<br>";echo db2_conn_errormsg();

die();

} else { // use the connection....}

An incorrect password will generate this output: Connection failed. SQL Err: 08001 Authorization failure on distributed database connection attempt. SQLCODE=-30082

68

Page 69: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Prepare/execute: resource or false

$sql = "SELECT * FROM BADLIB.SP_CUST WHERE CUST_ID > ?";

$stmt= db2_prepare($conn, $sql);

if (!$stmt) {echo 'The db2 prepare failed. ';echo 'SQLSTATE value: ' . db2_stmt_error() . '<BR>';echo ' Message: ' . db2_stmt_errormsg();

}

The error code and message might resemble: SQLSTATE value: 42704 Message: SP_CUST in BADLIB type *FILE not found. SQLCODE=-204

69

Page 70: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Other trace/debug ideas

Advanced use only: special libdb400 tracing driver: http://yips.idevcloud.com/wiki/index.php/PASE/Service

70

Page 71: DB2 and PHP in Depth on IBM i

Configuration

Page 72: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Prestart jobs in QSYSWRK by default

DB2 queries run in separate prestart jobs

72

Page 73: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Prestart job optimization

• QSQSRVR prestart jobs run in QSYSWRK • Or, if remote DRDA, QRWTSRVR in QUSRWRK • Configurable pool of jobs CHGPJE SBSD(QSYS/QSYSWRK) PGM(QSYS/QSQSRVR)

STRJOBS(*YES) INLJOBS(xx) THRESHOLD(xx) ADLJOBS(xx) MAXUSE(xx or *NOMAX)

• More on prestart db2 jobs and “server mode” § http://www.redbooks.ibm.com/abstracts/tips0658.html § http://www.mcpressonline.com/tips-techniques/database/techtip-

grab-control-of-the-db2-qsqsrvr-jobs.html § http://www.mcpressonline.com/database/db2/finding-sql-server-

mode-connecting-jobs.html

73

Page 74: DB2 and PHP in Depth on IBM i

Tip on shared read locks

Page 75: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

db2_free_result() clears “pseudo locks”

• In persistent mode, SELECT statements can cause *SHRRD (shared read) pseudo locks § See them in QSQSRVR jobs via the WRKOBJLCK command

• Pseudo locks help retain performance-enhancing cursors • Normally, CLRPFM and other exclusive ops will clear the locks

• If exclusive operations on your ‘i’ occur while your script is active, use db2_free_result() to release cursors$stmt=db2_exec($conn,"SELECT * FROM MYTABLE"); while($row=db2_fetch_array($stmt)) { echo "\n<br>"; var_dump($row); } db2_free_result ($stmt); // allow exclusive ops

75

Page 76: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Another way to clear “pseudo locks”

• If persistent connections create “shared read locks”

Run this command in your CL job stream before nightly exclusive lock attempts. ALCOBJ OBJ((MYLIB/MYFILE *FILE *EXCL *N)) CONFLICT(*RQSRLS)

if a member: ALCOBJ OBJ((MYLIB/MYFILE *FILE *EXCL MYMEMBER)) CONFLICT(*RQSRLS) Make sure you add a MONMSG immediately after the ALCOBJ command to handle any messages such as "cannot allocate..." which may arise normally.

76

Page 77: DB2 and PHP in Depth on IBM i

Library list jubilee (3 ways to set)

Page 78: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Most efficient way to set library list

• Let IBM i set library list based on user profile § No extra program calls required

• Use a user profile that has an “initial library list” in its job description (JOBD)

• Specify the user profile and i5_naming=ON § $conn = db2_connect('*LOCAL', 'LIBLUSER', 'PASS', array('i5_naming' => DB2_I5_NAMING_ON));

78

Page 79: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

“JOBD” technique in detail

Create jobd: CRTJOBD JOBD(QGPL/APPROD) INLLIBL(LIB1 LIB2 LIB3 QGPL)

Set jobd in user profile (or create new profile): CHGUSRPRF USRPRF(APPRODUSR) JOBD(QGPL/APPROD)

• In PHP, specify the user profile and i5_naming=ON § $conn = db2_connect('*LOCAL', 'LIBLUSER', ‘PASS’, array('i5_naming' => DB2_I5_NAMING_ON));

79

Page 80: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Middle ground: i5_libl

• $options array accepts 'i5_libl' • i5_libl is a space-delimited library list

§ 'i5_libl'=>'MYLIB YOURLIB ANYLIB’

• Causes ibm_db2 to run CHGLIBL at the middleware level

• Example: § $conn = db2_connect('*LOCAL' ,'MYUSER', 'MYPASS', array('i5_naming' => DB2_I5_NAMING_ON, 'i5_libl' => 'MYLIB1 MYLIB2’));

• Note: with persistent connections, CHGLIBL only run the first time in, so be sure to distinguish different jobs by user profile

80

Page 81: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

More work but most flexible

• If maximum flexibility required: § Run a command or program that sets up library list § Use CHGLIBL instead of ADDLIBLE

§ ADDLIBLE could generate “already in library list” error, causing toolkit to retrieve joblog (slow)

$db = db2_connect(‘*LOCAL', 'MYUSER', 'MYPASS', array('i5_naming' => DB2_I5_NAMING_ON));// connect to toolkit using existing DB2 conn $tkitConn = ToolkitService::getInstance($db, DB2_I5_NAMING_ON); // toolkit will share job with DB2 $tkitConn->setOptions(array('stateless' => true));

$tkitConn->CLCommand('CHGLIBL LIBL(NXSRTQA QGPL QTEMP)');

81

Page 82: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

db2_connect() example with $options

$database = 'MYDB';

$user = 'MYUSER'; $password = 'MYPASS';

$options = array('i5_naming' => DB2_I5_NAMING_ON,

'i5_libl' => 'MYLIB1 MYLIB2' );

$conn = db2_connect($database, $user, $password, $options);

if ($conn) {

echo "Connection succeeded.";

} else { echo "Connection failed.";

}

// MYTABLE will be found, if in library MYLIB1 or MYLIB2 $stmt=db2_exec($conn,"SELECT * FROM MYTABLE");

82

Page 83: DB2 and PHP in Depth on IBM i

New Global settings

Page 84: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Config file(s) for ibm_db2

• ibm_db2.ini •Main location for these settings •/usr/local/zendsvr6/etc/conf.d/ibm_db2.ini •A small file containing only ibm_db2 settings •Initial contents:extension=ibm_db2.so

• php.ini •Less common location •/usr/local/zendsvr6/etc/php.ini •Large file containing hundreds of settings •Add or modify settings under the section [ibm_db2]

84

Page 85: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

New ibm_db2 config options

• Shipped since Zend Server 7 • See change log for news

• http://www.youngiprofessionals.com/wiki/index.php/XMLSERVICE/PHPDB2ChangeLog

• Highlights coming right up

85

Page 86: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Highlights new (slide 1 of 2)

Setting Default What it does

ibm_db2.i5_sys_naming 0,1 1 enables library lists by default (even in LUW DB2 Connect 10.5)

ibm_db2.i5_blank_userid 0,1 When 0, blank user id/password become invalid

ibm_db2.i5_max_pconnect 0-n Cleans up persistent QSQSRVR jobs every so many connections

ibm_db2.i5_check_pconnect 0-4 Checks pconnect job. 0 means no test; 1-4 progressively more robust to test for a valid connection. If connection invalid, reconnect fresh

86

Page 87: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Highlights new (slide 2 of 2)

Setting Values What it doesibm_db2.i5_log_verbose 0,1 Log DB2 errors in /usr/local/

zendsvr(6)/var/logs/php.log Alan recommends 1

ibm_db2. i5_servermode_subsystem

[empty], *SAME, subsystem (QSYSWRK)

Exposes connection attribute SQL_ATTR_ SERVERMODE_ SUBSYSTEM to specify subsystem for QSQSRVR jobs

ibm_db2.i5_guard_profile 0,1 Restore job’s original “current user” at end of PHP request (this feature subject to change)

87

Page 88: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Alan’s recommended settings

/usr/local/zendsvr6/etc/conf.d/ibm_db2.ini extension=ibm_db2.so; log db2 errors in PHP error logibm_db2.i5_log_verbose=1

; Reset persistent connection after every 200 connection requestsibm_db2.i5_max_pconnect=200

; Quick check on each pconnect (conn. alive)ibm_db2.i5_check_pconnect=1

88

Page 89: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Defaults you may wish to change

/usr/local/zendsvr6/etc/conf.d/ibm_db2.ini ; no commitment controlibm_db2.i5_allow_commit=0; allow blank user/pw (change to 0 if you can)ibm_db2.i5_blank_userid=1

89

Page 90: DB2 and PHP in Depth on IBM i

Local development (on your PC)

Page 91: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

“How do I develop on non-i, deploy on i?”

• Developer goal: § Develop IBM i-based PHP code on a non-i machine (Linux,

Windows) § Connect to DB2 on IBM i using code that will also work on ‘i’

later in production

• Requires a separate product from IBM

91

Page 92: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

IBM DB2 Connect from Windows/Linux

•Purchase IBM’s “DB2 Connect” • http://www-01.ibm.com/software/data/db2/db2connect • Not free. We’ll see how this develops (no more Personal Edition)

•Your non-i computer will host a local “dummy” DB2 database that actually accesses DB2 on your IBM i

• Use the same ibm_db2 functions that you normally do • Configuration tips: http://yips.idevcloud.com/wiki/index.php/Tier2/

DB2Connect

•Library lists (system naming) available in DB2 Connect 10.5 on IBM i 7.1+

92

Page 93: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

ODBC alternative to DB2 Connect

•ODBC: no charge •ODBC not optimized for IBM i, not actively

maintained/supported •Some have had success with it • I don’t recommend for mission-critical systems but

you are welcome to try it, especially if your software already supports ODBC

•Less portable than DB2 Connect in moving app to/from IBM i

93

Page 94: DB2 and PHP in Depth on IBM i

Pagination (LIMIT/OFFSET)

Page 95: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Email from a PHP fan

“I’ve run into a little problem with DB2. I’m used to being able to use the LIMIT option in MySQL to set a range of records I want to view, perhaps the 20-29 records for instance.

“Could you tell me if there is or is not a way to do that on IBM i? My boss and I are beginning to think that such an option does not exist for use on the AS400 IBM i.”

• Yes, it can be done via a choice of two techniques • Useful for pagination (page-at-a-time logic) • LIMIT and OFFSET are non-standard, not in DB2

95

Page 96: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

1. ibm_db2 middleware technique// specify DB2_SCROLLABLE in db2_exec or db2_execute $startingRow = 20;

$endingRow = 29; $stmt = db2_execute($stmt, array('cursor' => DB2_SCROLLABLE)); $currentRow = $startingRow;

while (($currentRow <= $endingRow) && $row = db2_fetch_array($stmt, $currentRow)) { print "$row[0]\n"; $currentRow++;

}

Note additional param for row number: array db2_fetch_array ( resource $stmt [, int $row_number = -1 ] )

Disadvantage: middleware-dependent (only works with ibm_db2)

96

Page 97: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

2. SQL technique

• DB2’s row_number() and over() functions can select records by number in a recordset

• This simulates LIMIT and OFFSET

• Example coming up

97

Page 98: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Record range selection in DB2

Start with this: $queryString = "SELECT CUST_ID, COMPANY FROM SP_CUST order by CUST_ID”

Use row_number() and over() to limit the record selection: $queryString = "SELECT CUST_ID, COMPANY FROM (select row_number() over (order by CUST_ID) as rowid, CUST_ID, COMPANY from SP_CUST) as t where t.rowid between 20 and 29";

98

Page 99: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Or let Zend Framework handle it

• Use ZF’s Zend Db component from regular PHP • Builds SQL, hiding complexity of LIMIT/OFFSET

implementation, with cross-database code • Full script: https://github.com/alanseiden/Code-

Examples/blob/master/IBMi/DB2/ZF2LimitOffset.php // works with v2.3.2 of ZF2.$sql = new Sql($adapter);$select = $sql->select();$select->from('SP_CUST') ->where('CUST_ID > 1220') ->order('CUST_ID ASC') ->limit(10) ->offset(20);

99

Page 100: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Sample DB2 on i pagination script

coded by Zend’s Clark Everetts https://github.com/clarkphp/Code-Examples/tree/master/IBMi/pagination

100

Page 101: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

3. “Real” LIMIT and OFFSET

• New: LIMIT and OFFSET support in TR11 (7.1) and TR3 (7.2)

• https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/IBM%20i%20Technology%20Updates/page/OFFSET%20and%20LIMIT

• Coming soon in those Technology Refreshes • From Scott Forstie’s wiki page:

• LIMIT: alternative to FETCH FIRST x ROWS ONLY • OFFSET: skip rows in the query result

101

Page 102: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Stored procedure from Scott Forstie

102

Page 103: DB2 and PHP in Depth on IBM i

Performance tips

Page 104: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Performance tips

• Use persistent connections (see next slides) • Optimize SQL

§ A few specific tips (there are so many ways): • Avoid scalar functions (such as UPPER) in WHERE clause • OPTIMIZE FOR n ROWS (when know how many rows) • Check out IBM Rochester’s DB2 SQL performance class

• Index properly § Refer to Plan Cache and Index Advisor § Try Encoded Vector Indexes when appropriate

• System configuration § More memory, more memory! § Consider separate memory pool to keep data together

104

Page 105: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

DB2 query optimization

• IBM i has great tools

• I’ll share a couple of favorites ‣ Index Advisor ‣ SQL Plan Cache

• See IBM’s book • IBM i Database Performance and Query Optimization • http://pic.dhe.ibm.com/infocenter/iseries/v7r1m0/topic/rzajq/

rzajq.pdf

105

Page 106: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Index Advisor

• Recommends indexes across all queries • Now in web-based Navigator as well as thick client

106

Page 107: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

SQL Plan Cache

• Lets you see what queries are REALLY running, who’s running them, and how long they take

107

Page 108: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Persistent connections

•Create a pool of database jobs •Known as a “connection pool” •You will connect quickly because a job is waiting for you •DB2 will...

• Choose a QSQSRVR job when your PHP job first connects • Create new jobs to handle high workload

•The word “persistent” may be misleading •No guarantee that a browser session reconnects to same job •Between requests, cannot rely on maintaining state (QTEMP,

library lists). OK within a request, though

108

Page 109: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

db2_pconnect() to connect persistently

•resource db2_pconnect ( string $database , string $username , string $password [, array $options ] )

• Persistent is much faster than non-persistent § db2_pconnect can reuse connections, reducing the time needed

to connect (after the first time) to almost zero § SQL statement objects can also be reused, speeding queries

• How db2_pconnect() reuses connections § Connections defined by database, username, and password § Tries to reuse an existing connection matching these 3 params § db2_close() on a persistent connection does nothing § db2_pclose() forces the conn to close

109

Page 110: DB2 and PHP in Depth on IBM i

Tools for testing/development

Page 111: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

There’s more than STRSQL

• Operations Navigator (old reliable, but Windows only)

• Web-based navigator § Starting to get quite good, with Run SQL window just added § http://myibmi:2001

§ IBM i Access § New client for Mac, Linux, Windows 10+ § http://www-03.ibm.com/systems/power/software/i/access/

• Other tools such as SQL Workbench/J, Data Studio § http://www.sql-workbench.net/, https://www.ibm.com/

developerworks/ibmi/library/i-debugger-db2-i/

111

Page 112: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

SQL Workbench/J

112

Page 113: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

SQL Workbench/J

113

Page 114: DB2 and PHP in Depth on IBM i

Choose a CCSID

Page 115: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

CCSID is magical (when it works)

• Coded Character Set Identifier (CCSID) helps convert data from EBCDIC to ASCII

• DB2 operates in multiple language environments § Each human language requires a different conversion

• CCSIDs are listed here § http://www-01.ibm.com/software/globalization/ccsid/ccsid_registered.html

• I use CCSID 37, good for USA, Canada, Netherlands, Portugal, Brazil, Australia, New Zealand

115

Page 116: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Default CCSID of 65535 can cause trouble

•QCCSID value is 65535 by default •65535 means to treat data as hex or “binary,” not to be converted

•When a table/file has CCSID 65535, you get gibberish SELECT CUST from CUSTFILE WHERE ID = 1

•Result: •$#%#%#(*#$

•A clue in a Zend Server startup message •“The Zend Server Apache job CCSID is set to 65535. This setting

might have unpredictable results when accessing data base data.”

116

Page 117: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Solutions (old and new)• SQL Casting

§ CAST data to the proper EBCDIC CCSID, such as 37 § Requires that you provide the data type such as char(6) § SELECT CAST(CUST as char(6) CCSID 37) FROM CUSTFILE WHERE ID = 1

* Casting still required when CCSID explicitly set at field level (such as in older JDE systems)

• System-wide settings § CHGSYSVAL SYSVAL(QCCSID) VALUE(37)

• 37 is mine; yours will vary • Often safe to change, but check with ERP vendor (e.g. JDE)

§ Add to Apache ZENDSVR configuration file • /www/zendsvr/conf/httpd.conf

DefaultFsCCSID 37 CGIJobCCSID 37

117

Page 118: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

DB2 and PHP Resources

• IBM § IBM_DB2 manual and open source repository

• http://php.net/ibm_db2, http://pecl.php.net/package/ibm_db2 § DeveloperWorks wiki

• http://ibm.com/developerworks/ibmi § Many details about PHP and DB2 connections

• http://www.youngiprofessionals.com/wiki/index.php/PHP/DB2Connection

• Zend § Zend Server for IBM i

• http://www.zend.com/en/products/server/zend-server-ibm-i § Forums for PHP on IBM i

• http://forums.zend.com/viewforum.php?f=67

118

Page 119: DB2 and PHP in Depth on IBM i

Resources

Page 120: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

For more info and learning

• DB2 for i SQL reference • http://www-01.ibm.com/support/knowledgecenter/

ssw_ibm_i_72/db2/rbafzintro.htm?lang=en

• Young i PHP/Db2 page • http://www.youngiprofessionals.com/wiki/index.php/PHP/

DB2Documents

• IBM DB2 forum § https://www.ibm.com/developerworks/community/forums/html/

forum?id=11111111-0000-0000-0000-000000000292&ps=50

120

Page 121: DB2 and PHP in Depth on IBM i

Questions

Page 122: DB2 and PHP in Depth on IBM i

DB2 and PHP: EssentialsSeiden Group

Contact and tips

Alan Seiden Seiden Group Ho-Ho-Kus, NJ

122

[email protected] ● 201-447-2437 ● twitter: @alanseiden

Free newsletter: http://seidengroup.com/tips

Please give feedback on this talk: https://joind.in/talk/34c69